Scams & FraudAdvanced6 min read

Business email compromise: how a spoofed email drains a wire

The most expensive scam in the world doesn't hack your bank — it impersonates a trusted party and asks you to send the money yourself. Verification protocols and insurance for households and small businesses.

Business email compromise (BEC) is, by dollars lost, the most damaging category of cybercrime — billions each year, dwarfing ransomware. Its power is that it involves almost no hacking. A criminal compromises or spoofs a trusted email account — a vendor, an executive, a title company, a lawyer — and simply asks a person with payment authority to send a wire, change bank details, or 'update the account for future payments.' The victim isn't breached; the victim is persuaded. Households face the same attack at life's highest-stakes moments: closing on a home, paying a contractor, settling an estate. Because the money moves by wire and is sent willingly, it is exceptionally hard to claw back — which is why the entire defense lives in the seconds before you hit send.

The anatomy of a BEC attack

  1. Reconnaissance: the attacker learns your relationships — often by quietly reading a compromised inbox for weeks, watching how invoices and closings work, and noting who pays whom.
  2. Impersonation: they spoof or take over a trusted email, sometimes registering a near-identical domain (rnicrosoft.com for microsoft.com) that reads correctly at a glance.
  3. The ask: a routine-sounding request to wire funds or change payment instructions, timed to a real transaction so it fits your expectations perfectly.
  4. The pressure: urgency and secrecy — 'the closing is today,' 'I'm in a meeting, just handle it,' 'don't loop anyone else in yet.'
  5. The vanish: once wired, funds are pulled through mule accounts within hours and are usually gone by the time anyone notices.
The $310,000 that a phone call would have saved
The Okonkwos are closing on a home. Two days before, they get an email from their 'title company' with updated wire instructions — the letterhead is perfect, the loan officer's name is right, the thread even quotes their earlier real emails. They wire $310,000 to the new account. The email was from a domain one letter off from the real one; the attacker had been reading the title company's inbox for weeks and knew every detail of the closing. By the time the real title company calls asking where the funds are, the money has been split across mule accounts and moved offshore. Because they acted fast and filed an IC3 report the same day, the FBI freezes and recovers about $95,000 — but $215,000 is gone. A single phone call to the title company's known number, using the instructions from the original signed contract, would have exposed the switch instantly and cost nothing.

The one rule that defeats it: out-of-band verification

Nearly every BEC loss traces to a single missing step — confirming a payment or a change of instructions through a different channel than the one that requested it. If the request came by email, you verify by phone. And not by the phone number in the email (which the attacker controls) but by a number you already had — from a signed contract, a prior statement, the back of a card, or a directory. This 'out-of-band' verification is the entire defense, and it works because the attacker who owns the email channel almost never also controls your independent phone line to the real party.

TriggerRequired actionNever acceptable
Any new or changed bank/wire detailsCall known number to confirm; verbally read back accountConfirming via email reply or number in the email
Any wire over your thresholdTwo-person approval + callback verificationOne person sending on urgency alone
'Urgent' or 'confidential' payment requestSlow down; treat urgency as a red flag itselfActing faster because it's urgent
Executive/family 'emergency' askVerify with a pre-agreed code word or direct callTrusting a text or email alone
A verification protocol worth writing down

Hardening the technical side

  • Protect the inbox: app-based 2FA on all business and personal email prevents the account takeover that makes the most convincing BEC possible.
  • Watch for look-alike domains: hover over sender addresses; register common misspellings of your own domain so criminals can't.
  • Enable email authentication (SPF, DKIM, DMARC) if you run a business domain, to make spoofing harder.
  • Flag external email: many mail systems can tag messages from outside your organization, which instantly exposes an 'internal' request that isn't.
  • Separate duties: the person who can change vendor bank details should not be the same person who approves the payment.
Wires are willing, and willing means unprotected
Because you authorized the wire, consumer fraud protections that cover unauthorized card charges largely don't apply. Banks are not generally required to reimburse a wire you sent yourself, even to a criminal. Recovery depends entirely on speed — a same-day IC3 report and bank recall request can sometimes freeze funds — but the honest planning assumption is that a wire sent to a scammer is gone. Prevention is the only reliable protection.

Insurance: the backstop when verification fails

For small businesses, dedicated coverage exists and is worth pricing: cyber insurance and specifically 'social engineering fraud' or 'funds transfer fraud' endorsements. The critical detail is that standard crime policies often exclude BEC precisely because the transfer was authorized by an employee — so the social-engineering endorsement is the piece that actually covers this scenario. Read for it by name. For households, there is no true equivalent, though some homeowner or identity policies offer limited fraud coverage; the household 'insurance' is procedural — the verification habit and, for home closings, confirming wire details in person or by known phone before funding.

Set a family and business code word
Agree on a private verification word with family (for 'emergency' money requests) and a callback protocol with your business's finance function. When a panicked 'grandchild' or a 'CEO' emails for an urgent transfer, the code word or mandatory callback turns an emotional ambush into a two-second check the real person can pass and the impostor cannot. It costs nothing and neutralizes the entire pressure tactic BEC depends on.

The bottom line

BEC is the world's costliest scam because it skips the hacking and simply convinces a trusted person to send the money — willingly, by wire, irreversibly. The defense is almost absurdly cheap: verify every payment and every change of banking details out-of-band, using a number you already had, before funds move. Harden your email with app-based 2FA, separate who can change details from who approves payments, and for a business, buy the social-engineering fraud endorsement by name. Treat urgency and secrecy as the attack, not the context — and remember that a wire, once sent, rarely comes back.

Check your understanding

1 of 3
An email that looks like your title company sends 'updated' wire instructions, quoting your earlier real emails, from a domain one letter off from the real one. What is 'out-of-band verification'?

Not quite — try again.

The Worth letter

Get smarter about money every week

One email, no spam — practical guides and Worth updates. Unsubscribe anytime.

Put this into practice

Worth tracks your accounts, budgets, and goals — so the concepts in this article aren't just theory.

Start free trial